PT-2026-31975 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-03-29

·

Updated

2026-04-10

·

CVE-2026-35664

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.25
Description OpenClaw contains an authentication bypass issue in the raw card send surface. This allows unpaired recipients to create legacy callback payloads, bypassing DM pairing restrictions and reaching callback handling without authorization. The issue was resolved by rejecting legacy raw-card command payloads, ensuring callbacks remain on the normal paired path.
Recommendations Update to version 2026.3.25 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35664
GHSA-77W2-CRQV-CMV3

Affected Products

Openclaw